CDOE | Certified Defense Operations Expert

Blue Team • SOC • DFIR

Become the analyst who can find what others miss.

CDOE turns alerts, logs, memory, network traffic, and attacker behavior into one connected investigation. Learn to hunt threats, contain incidents, engineer stronger detections, and brief leadership with confidence.

50+ Hours On-DemandBeginner → IntermediateLifetime AccessSeven-Day Practical
INVESTIGATION ACTIVESOC / CASE 047
Suspicious PowerShell ChainEndpoint telemetry • MITRE T1059.001
92
Outbound C2 BeaconDNS + proxy correlation
81
Lateral MovementAuthentication timeline reconstructed
74
What CDOE Proves

Operational skill—not memorized vocabulary.

You will learn the complete defensive workflow: recognize meaningful activity, validate evidence, reconstruct an intrusion, contain the threat, improve detection coverage, and communicate what happened in a professional incident report.

01

Investigate the Signal

Turn noisy alerts into a defensible conclusion by correlating endpoint, identity, DNS, firewall, and application telemetry.

02

Reconstruct the Attack

Build a reliable timeline from initial access through persistence, lateral movement, command-and-control, and impact.

03

Lead the Response

Contain and eradicate safely, preserve evidence, document decisions, and give leadership a clear path to recovery.

Inside the Defensive Lab Range

Six disciplines. One connected mission.

The labs are designed as realistic investigations, not isolated button-clicking exercises. Each discipline strengthens the next until you can handle a complete incident independently.

SI

SIEM & Log Analysis

Query and correlate Windows, Linux, firewall, DNS, and application logs in Splunk and Elastic-style workflows.

SPLUNKELASTICMITRE ATT&CK
TH

Threat Hunting

Form hypotheses, inspect process trees, uncover living-off-the-land activity, and detect command-and-control beacons.

LOLBINSDNSPCAP
IR

Incident Response

Work ransomware, business email compromise, and advanced intrusion scenarios from triage through recovery.

CONTAINERADICATERECOVER
DF

Digital Forensics

Analyze Windows disks and memory, recover artifacts, examine the registry, and build evidence-backed timelines.

VOLATILITYWINDOWSTIMELINES
MA

Malware Analysis

Move from safe static inspection to controlled behavioral analysis and extract indicators defenders can act on.

STATICDYNAMICYARA
DE

Detection Engineering

Write, test, tune, and explain Sigma and YARA detections while measuring false positives and coverage gaps.

SIGMAYARAVALIDATION
Custom Labs That Build Toward the Final

Every investigation makes the next one harder—and you stronger.

You begin with guided evidence analysis, then progress into increasingly independent incidents. By the final practical, you are responsible for the decisions, the evidence, and the report.

STAGE 01

Guided Analysis

Learn the tools and reasoning process with structured objectives, curated telemetry, and instructor direction.

STAGE 02

Incident Scenarios

Investigate realistic ransomware, account compromise, insider-threat, and command-and-control activity.

STAGE 03

Readiness Runs

Work under uncertainty with more noise, fewer hints, competing priorities, and formal reporting requirements.

STAGE 04

Final Capstone

Own a complete enterprise investigation and prove that you can turn evidence into decisive action.

How the Labs Run

Built to feel like an operations floor—not a quiz.

01

Isolated Investigation Environments

Work inside dedicated scenarios designed for safe analysis, repeatable practice, and hands-on experimentation.

02

Live Telemetry & Realistic Noise

Separate normal business behavior from malicious activity across multiple evidence sources and timelines.

03

Clean Scenario Resets

Restart an exercise, test a different theory, and repeat difficult workflows until the process becomes instinctive.

04

Progressive Independence

Guidance deliberately decreases as your analytical judgment, documentation, and response confidence increase.

Seven-Day Practical Exam

The Final Defensive Capstone

Enter an isolated enterprise environment with a real compromise to investigate. You will use SIEM, endpoint, network, and forensic evidence to determine what happened—and what the organization must do next.

Identify patient zero
Trace lateral movement
Determine affected data
Contain and eradicate
Engineer new detections
Build the incident timeline
Document evidence
Deliver the final report
50+ HoursOn-demand training
LifetimeCourse access
7 DaysPractical exam
1 FreeExam retake
$400One-time enrollment
Ready to Defend What Matters?

Train for the investigation you cannot afford to mishandle.

Build the technical judgment, evidence discipline, and communication skills expected from a capable SOC and incident-response professional.

Start CDOE — $400

Includes one complimentary exam retake. Additional retakes are $150.